How the HIPAA Omnibus Final Rule Applies to E-mail Communication with Patients
The Omnibus Final Rule was introduced at the start of the year and covered organizations – which now include business associates and their subcontractors – now need to update procedures and policies to comply with the new regulations if they have not already done so. The deadline for compliance with the new rule is September 23, 2013 and any covered entity found not to have implemented the required changes after this date could incur a financial penalty up to $1.5 million. The new changes have been criticized by some members of the healthcare community; however the changes are necessary in order to improve the rights of patients to access their medical data. The Omnibus Rule now allows them to have much greater autonomy and make decisions about how their medical information is communicated to them. If a patient is comfortable receiving information via E-mail this has previously presented a problem for healthcare companies. E-mails can be intercepted, the emails are often stored unsecured servers – where they can remain indefinitely – and there is no guarantee that the...
Mammoth HIPAA Data Breach Exposes 4M Patient Records
Advocate Health Care, one of the nation’s largest healthcare providers, has announced that it has suffered a major HIPAA security breach after four unencrypted laptops were stolen from the Advocate Medical Group administrative buildings in Park Ridge, Illinois on July 15. The laptops contained the records of over 4 million individuals, making this the second largest data security breach ever recorded. This HIPAA breach has affected almost as many patients as the TRICARE Management Activity breach which exposed the data of 4.9 million individuals in 2011. The database on the laptops included personal identifiable information together with clinical data on patient illnesses, Social Security numbers, dates of birth, medical record numbers, treating doctors, health insurance details and patient names and addresses. The theft has been reported to law enforcement; however the laptops and data have not yet been recovered. The Office for Civil Rights of the Department of Health and Human Services has been notified of the security breach and officials have confirmed that an investigation...
BYOD Schemes Prove Popular With Nurses
According to a recent report from Spyglass Consulting, it is not just doctors who are embracing medical BYOD schemes; nurses too are now participating and 69% of those polled said they bring their own mobile device to work with them. Mobile devices cannot be used for all work activities, as the vast majority of healthcare providers operate strict controls over what the devices can be used for. One of their main uses is for organizing staff schedules and maintaining calendars, with more than half of healthcare staff using their devices for this purpose in addition to checking email according to healthcare mobile phone usage research conducted by Absolute Software. 36% said they were using the devices to access PHI. For PHI to be accessed without causing a HIPAA violation, additional security controls must be employed to secure the data being sent. Mobile phones are not secure, can easily be lost or stolen and the messages they send can be intercepted. Secure texting solutions exist, and these must be used for communicating any PHI via SMS message. E-mail encryption is also required...
53 Percent of Physicians Use a Smartphone, Tablet and Computer at Work
Doctors are clearly embracing new technology if the results of a recent survey are representative of the nation as a whole. Epocrates, a mobile reference material vendor, has recently conducted a survey on 1,063 mid-level practitioners and physicians asking them about the use of mobile devices in the workplace. The survey results show a marked increase in the usage of all mobile devices, with a particularly telling statistic being the percentage of doctors who are using all three types of device categorized in the study: Smartphones, tablets, and desktop/laptops. These “digital omnivores” as they are referred to in the study have increased from 28% in 2012 to 53% this year. As more healthcare providers implement BYOD schemes, or provide devices to healthcare professionals, the number of digital omnivores in healthcare is expected to increase, and significantly so according to Epocrates researchers. They predict the number will grow to 82% over the course of the coming year. Oncologists Most Likely to use Smartphones, Tablets and Desktops at Work Oncologists were the most...
Cogent Healthcare Contractor HIPAA Error puts Patient PHI in Search Engines
Cogent Healthcare has issued a statement announcing that M2ComSys, a contractor used for transcription services, was responsible for a HIPAA breach that exposed the data of 32,000 patients across America. The data breach not only left medical information accessible to unauthorized third parties, but it also saw some of that protected health information indexed by Google. This is the second reportable HIPAA data breach suffered by Cogent Healthcare, according to the Office for Civil Rights. The security breach occurred between May 5, 2013 and June 24, 2013, with data being made available due to a firewall not being activated. Without the firewall in place there were no restrictions as to who could access the data, which violates HIPAA Privacy and Security Rules. The data included personally identifiable information, medical record numbers, medical histories and patient contact details, although there were no Social Security Numbers present in the data. M2ComSys was employed to transcribe notes made by physicians and held the data on what it believed to be a secure server, although...



